Insurers and brokers operating in Singapore now face a formal regulatory framework for governing artificial intelligence, with compliance required from October 2027 and full implementation by October 2028.
The Monetary Authority of Singapore (MAS) on October 7 released its Guidelines on Artificial Intelligence (AI) Risk Management, a framework that applies to all financial institutions in the city-state, including insurers, reinsurers, and intermediaries. The guidelines require firms to manage AI risks at both the enterprise level and individual use case level, while allowing each institution to scale its approach based on risk materiality.
The provision with the most direct implications for brokers and intermediaries is the third-party AI accountability rule. Insurers remain fully accountable for AI used in the services they deliver, including AI developed, operated, or provided by third parties.
As MAS-regulated intermediaries, brokers fall directly within the guidelines. Any AI a brokerage uses, whether built in-house or bought from a vendor, comes under the same expectations that apply to insurers.
In practice, that means brokers will need to know where AI is being used across their business. Common examples include tools for drafting client correspondence, summarising policy documents, comparing quotes, handling client enquiries and processing claims notifications. Each use case will need to be logged in an inventory, assessed for how material its risks are to the firm and its clients, and subject to controls proportionate to those risks.
The third-party rule makes that particularly significant. Many brokers rely on AI built into the software they license, such as broking platforms, customer relationship systems or document tools, rather than developing their own. Under the guidelines, using a vendor’s tool does not transfer responsibility to the vendor. Brokers must obtain sufficient assurance from their providers, assess whether each tool is suitable for its intended use, and apply compensating controls where gaps arise. If the risks cannot be brought within the firm’s risk appetite, MAS expects it to consider limiting, suspending or replacing the service.
The rules are proportionate. A brokerage whose AI use is unlikely to have a material impact on the firm, its clients or other stakeholders may only need basic policies and procedures. But firms will need to have assessed their AI use to reach that conclusion, and to be able to show that they have.
Brokers will also feel the rules indirectly. Their insurer partners increasingly use AI-powered platforms for quoting, underwriting, claims processing and policy administration, and those insurers face the same third-party obligations. If an insurer decides a third-party AI tool falls outside its risk appetite, the result could be changes to the platforms brokers use daily, affecting processing times, service delivery or product availability.
The focus on third-party risk aligns with broader industry guidance. In the Chambers and Partners Insurance & Reinsurance 2026 guide for Singapore, law firm RPC Premier Law noted that “insurers should look to take a proactive approach to managing the flow of risks from the use of AI.”
For brokers, the year before the first compliance date is the time to take stock. Mapping where AI is used, checking what assurance vendors can provide, and deciding which uses are material will be considerably easier now than in the months before October 2027.
The MAS framework sets out four key expectations.
Financial institutions must strengthen oversight of AI risks with clear accountabilities. Boards and senior management are expected to set roles, responsibilities, risk appetite, and governance frameworks. MAS noted that firms may use existing governance structures and do not need to establish a dedicated AI committee solely to meet this expectation.
Firms must also identify, assess, and manage AI risks across the full AI life cycle. This includes maintaining inventories of AI use cases, assessing risk materiality, and applying proportionate controls covering data governance, testing, human oversight, cybersecurity, monitoring, and change management.
MAS flagged the growing use of agentic AI systems that can operate autonomously and access tools, and said it intends to consult the financial sector further on agentic AI guidance in 2027.
Firms should apply the guidelines in a risk-proportionate manner. Institutions whose AI use is unlikely to have a material impact on the firm, its customers, or other stakeholders may put basic policies and procedures in place.
The guidelines do not arrive without support. In March 2026, MAS concluded phase two of Project MindForge, publishing an AI Risk Management Toolkit developed with a consortium of 24 banks, insurers, capital markets firms, and other industry participants, according to Fintech News Singapore.
The toolkit includes an AI Risk Management Operationalisation Handbook with practical guidance on implementing controls, along with case studies from participating firms. The handbook’s four sections mirror the guidelines: scope and oversight, AI risk management, AI life cycle management, and organisational enablers.
In a keynote speech at the Life Insurance Association of Singapore’s (LIA) annual luncheon in March 2026, MAS assistant managing director Marcus Lim urged insurers to think critically about their AI deployment: “When you deploy an AI model, what are the conditions under which you will suspend its use?”
The guidelines take effect on October 7, 2027. Firms must meet the expectations in Sections 3 to 4 by that date, and Sections 5 and 6 by October 7, 2028. The release follows a public consultation launched in November 2025, which drew broad support for the principles-based approach.
“AI has significant potential to improve financial services, from enhancing customer outcomes and strengthening risk management to improving productivity and enabling new products and services. Realising these benefits sustainably requires financial institutions to understand and manage the risks that come with increasingly capable AI systems,” said Ho Hern Shin, deputy managing director at MAS.
Read next: Insurers rate themselves AI leaders but none has rebuilt distribution around it - KPMG
Singapore is not acting in isolation. In April 2026, the Australian Prudential Regulation Authority (APRA) issued a letter to industry calling for a “step-change” in AI-related risk management, warning that governance gaps and assurance practices were not keeping pace with AI adoption across banks and insurers.
At the global level, the Financial Stability Board (FSB) in June 2026 published a consultation report proposing 12 sound practices for responsible AI adoption by financial institutions. A final report is expected in October 2026.
In Hong Kong, the Insurance Authority (IA) joined the Hong Kong Monetary Authority (HKMA), Securities and Futures Commission (SFC), and Mandatory Provident Fund Schemes Authority (MPFA) in March 2026 to launch GenAI Sandbox++, extending the city’s generative AI sandbox framework to the insurance sector, according to law firm King & Wood Mallesons.
The full MAS guidelines and the response to feedback from the November 2025 consultation are available on the regulator’s website.